Multiple vulnerabilities

From: LuMiWa <lumiwa_at_dismail.de>
Date: Thu, 10 Jul 2025 19:29:47 UTC
Hi!

There are many problems in ports, clamav so long but there are no any
updates in packages. How long is usual the time that ara packages
build, please or should I build them from ports.
I am running FreeBSD 14.3-RELEASE and using latest packages.

Thank you

vulnxml file up-to-date
git-2.50.0 is vulnerable:
  git -- multiple vulnerabilities
  CVE: CVE-2025-48386
  CVE: CVE-2025-48385
  CVE: CVE-2025-48384
  CVE: CVE-2025-46835
  CVE: CVE-2025-27614
  CVE: CVE-2025-27613
  WWW: https://vuxml.FreeBSD.org/freebsd/2a4472ed-5c0d-11f0-b991-291fce777db8.html

clamav-1.4.2_4,1 is vulnerable:
  clamav -- ClamAV PDF Scanning Buffer Overflow Vulnerability
  CVE: CVE-2025-20260
  WWW: https://vuxml.FreeBSD.org/freebsd/3dcc0812-4da5-11f0-afcc-f02f7432cf97.html

  clamav -- ClamAV UDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
  CVE: CVE-2025-20234
  WWW: https://vuxml.FreeBSD.org/freebsd/6c6c1507-4da5-11f0-afcc-f02f7432cf97.html

xorg-server-21.1.16,1 is vulnerable:
  xorg server -- Multiple vulnerabilities
  CVE: CVE-2025-49180
  CVE: CVE-2025-49179
  CVE: CVE-2025-49178
  CVE: CVE-2025-49177
  CVE: CVE-2025-49175
  WWW: https://vuxml.FreeBSD.org/freebsd/b14cabf7-5663-11f0-943a-18c04d5ea3dc.html

  xorg server -- Multiple vulnerabilities
  CVE: CVE-2025-49176
  WWW: https://vuxml.FreeBSD.org/freebsd/8df49466-5664-11f0-943a-18c04d5ea3dc.html

5 problem(s) in 3 package(s) found.

-- 
“I’ve entered the world of wine without any professional training,
 but a definite appetite for good bottles.”

― Sidonie-Gabrielle Colette